Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains how OneID(the “Service”, at oneid.club and the OneID mobile app) collects, uses, shares, and protects your personal data. OneID is operated by Capritech Global Services Pvt. Ltd.(“CTGS”, “we”, “us”), an Indian company. We act as a Data Fiduciaryunder India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). By using OneID you agree to this Policy.
The heart of OneID: you verify your government ID once. When you check in at a partner hotel, the hotel receives only an attested summary of your identity — with your explicit, per-visit consent. Hotels never receive your raw documents, and you can see and revoke every access from your wallet.
1. Data we collect
We collect only what is needed to verify your identity and let you share it on your terms:
- Account data: your mobile phone number (used to sign in via OTP) and, optionally, email.
- Identity data from your verified document: full name, date of birth, gender, nationality, and the photograph printed on the document.
- Document reference: the document type and issuer, plus a masked identifier (only the last 4 digits) and a one-way cryptographic hash. We never store your full Aadhaar number or images of your documents.
- Face verification data (optional): if you choose to add a face scan, a selfie photograph and a mathematical facial template (embedding) used to confirm it is you.
- Consent and activity records: which hotel accessed which fields, when, and until when; your check-in history; and an append-only audit trail.
- Technical data: IP address and device information, retained for security and fraud prevention.
2. How we verify identity (DigiLocker & Aadhaar)
We do not perform Aadhaar authentication or eKYC ourselves. You verify your identity through government-sanctioned, consent-based channels:
- DigiLocker (MeitY): you authorise DigiLocker to share your government-issued document with OneID. Aadhaar is returned pre-masked by DigiLocker.
- Aadhaar Paperless Offline e-KYC: you upload the XML you download from UIDAI. We extract only the fields above and store the masked reference — never the full number.
- Manual documents (passport, driving licence, voter ID): reviewed before your OneID activates; only the masked number is stored.
3. Biometric (face) data
Face verification is optional and, if used, is processed entirely on our own servers in India using our own technology. Your selfie and facial template are never shared with any third party or external vendor, are used only to confirm your identity, are never disclosed to hotels beyond the verified photo on your attested card, and are permanently deleted when you request erasure or remove face verification.
4. How we use your data
- To create and secure your OneID account and verify your government identity.
- To generate an attested guest card and share it with a hotel only when you consent at check-in.
- To help hotels meet their legal duties — the digital guest register and, for foreign nationals, the Form C report to the FRRO.
- To prevent fraud and abuse, and to comply with applicable law.
We do not sell your personal data or use it for advertising.
5. What hotels receive (data minimisation)
When you consent to a check-in, the partner hotel receives an attested card only: your name, photo, date of birth, gender, nationality, document type, masked document number, and verification status. Hotels never receive your phone number, address, full document number, document images, or facial template.
6. Retention
- Share codes: 5 minutes, single use.
- Consent records: for the duration of the stay plus a limited window, after which access expires.
- Check-in records: retained by the hotel as required by state guest-register and Foreigners Act rules.
- Erasure: on request we scrub your personal data and retire your OneID; records the hotel must legally keep for its own register remain with the hotel.
7. Your rights (DPDP Act)
As a Data Principal you may:
- Access a summary of your data and how it is processed;
- Correct or complete your data;
- Erase your data once its purpose is served;
- Withdraw consent — revoke any hotel’s access from your wallet at any time;
- Grieve — raise a complaint with our Grievance Officer.
You can exercise access, correction, and erasure directly in the app or web wallet under Privacy & your data, or by emailing us (Section 10). We respond within the timelines set by the DPDP Act.
8. Security
Passwords and OTPs are hashed; API keys are stored only as hashes; access tokens are short-lived; every identity access is recorded in an append-only audit trail. Full Aadhaar numbers and document images are never stored. Despite our safeguards, no method of transmission or storage is perfectly secure.
9. Children
OneID is intended for individuals aged 18 and above. We do not knowingly create accounts for children without verifiable parental consent as required by the DPDP Act.
10. Grievance Officer & contact
For any privacy question, request, or complaint, contact our Grievance Officer:
Grievance Officer, OneIDCapritech Global Services Pvt. Ltd.
302, Tanishka Commercial Building, Akurli Road, Kandivali East, Mumbai 400101, India
Email: ashish@ctgs.in
11. Changes
We may update this Policy; material changes will be posted here with a new “Last updated” date. See also our Terms & Conditions.